Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.1
CVE-2018-9083
In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be used to log in to the device …
System Management Module Firmware
1.06+
MEDIUM 5.9
CVE-2018-9073
Lenovo Chassis Management Module (CMM) prior to version 2.0.0 utilizes a hardcoded encryption key to protect certain secrets. Possession of the key c…
Chassis Management Module Firmware
2.0.0+
CRITICAL 9.8
CVE-2018-0680
Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) uses hard-coded credentials, which ma…
Debun Imap
after 3.3p_r4.0
CRITICAL 9.8
CVE-2018-0681
Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) uses hard-coded credentials, which ma…
Debun Imap
after 3.3p_r4.0
CRITICAL 9.8
CVE-2018-15439EPSS 50%
A vulnerability in the Cisco Small Business Switches software could allow an unauthenticated, remote attacker to bypass the user authentication mecha…
Sg200 50 Firmware
Mitigation only
CRITICAL 9.8
CVE-2018-19069
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Fir…
I5 Application Firmware
No fix yet
HIGH 7.5
CVE-2018-19065
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Fir…
I5 Application Firmware
No fix yet
HIGH 7.5
CVE-2018-19066
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Fir…
I5 Application Firmware
No fix yet
CRITICAL 9.8
CVE-2018-19067
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Fir…
I5 Application Firmware
No fix yet
CRITICAL 9.8
CVE-2018-19063
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Fir…
I5 Application Firmware
No fix yet
HIGH 8.8
CVE-2018-11062
Integrated Data Protection Appliance versions 2.0, 2.1, and 2.2 contain undocumented accounts named 'support' and 'admin' that are protected with def…
Emc Integrated Data Protection Appliance
after 2.2
HIGH 8.8
CVE-2018-10532
An issue was discovered on EE 4GEE HH70VB-2BE8GB3 HH70_E1_02.00_19 devices. Hardcoded root SSH credentials were discovered to be stored within the "c…
4gee Firmware
No fix yet
CRITICAL 9.8
CVE-2018-13342
The server API in the Anda app relies on hardcoded credentials.
Anda
Mitigation only
CRITICAL 9.8
CVE-2018-12668
SV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B devices have a Hard-coded Password.
H.264 Poe Ip Camera Firmware
No fix yet
CRITICAL 9.8
CVE-2018-17894
NUUO CMS all versions 3.1 and prior, The application creates default accounts that have hard-coded passwords, which could allow an attacker to gain p…
Nuuo Cms
after 3.1
HIGH 8.1
CVE-2018-17896
Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The affected controllers utilize hard-coded credentials wh…
Fcj Firmware
Mitigation only
MEDIUM 6.5
CVE-2018-17919
All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use an undocumented user account "default" with…
Xmeye P2p Cloud Server
Mitigation only
CRITICAL 9.8
CVE-2018-5399
The Auto-Maskin DCU 210E firmware contains an undocumented Dropbear SSH server, v2015.55, configured to listen on Port 22 while the DCU is running. T…
Dcu 210e Firmware
3.7+
CRITICAL 9.3
CVE-2018-1742
IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its ow…
Security Key Lifecycle Manager
after 3.0.0.1
CRITICAL 9.8
CVE-2018-15427EPSS 7%
A vulnerability in Cisco Video Surveillance Manager (VSM) Software running on certain Cisco Connected Safety and Security Unified Computing System (U…
Video Surveillance Manager
Mitigation only
CRITICAL 9.8
CVE-2018-15389
A vulnerability in the install function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the…
Prime Collaboration
Mitigation only
HIGH 7.5
CVE-2018-15753
An issue was discovered in the MensaMax (aka com.breustedt.mensamax) application 4.3 for Android. The use of a Hard-coded DES Cryptographic Key allow…
Mensamax
No fix yet
HIGH 7.5
CVE-2018-17217
An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2. There is a hardcoded encryption key.
Thingworx Platform
after 8.2
CRITICAL 9.8
CVE-2018-8856
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software contains hard-coded cryptographic key, which it uses for encryption o…
E Alert Firmware
Mitigation only
CRITICAL 9.8
CVE-2018-16957
The Oracle WebCenter Interaction 10.3.3 search service queryd.exe binary is compiled with the i1g2s3c4 hardcoded password. Authentication to the Orac…
Webcenter Interaction
Mitigation only
HIGH 8.8
CVE-2018-0663
Multiple I-O DATA network camera products (TS-WRLP firmware Ver.1.09.04 and earlier, TS-WRLA firmware Ver.1.09.04 and earlier, TS-WRLP/E firmware Ver…
Ts Wrlp Firmware
after 1.09.04
MEDIUM 5.9
CVE-2018-16546
Amcrest networked devices use the same hardcoded SSL private key across different customers' installations, which allows remote attackers to defeat c…
Amcrest Ipc Hx1x3x Lexus Eng N Amcrest
Mitigation only
HIGH 7.5
CVE-2018-14901
The EPSON iPrint application 6.6.3 for Android contains hard-coded API and Secret keys for the Dropbox, Box, Evernote and OneDrive services.
Iprint
No fix yet
HIGH 7.5
CVE-2018-13819
A hardcoded secret key, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows attackers to access sensitive information.
Unified Infrastructure Management
Mitigation only
HIGH 7.5
CVE-2018-13820
A hardcoded passphrase, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows attackers to access sensitive information.
Unified Infrastructure Management
No fix yet